const authMiddleware = (req, res, next) => {
  if (!req.session || !req.session.user) {
    return res.status(401).json({ 
      error: '未授权访问',
      message: '请先登录' 
    });
  }

  req.user = req.session.user;
  next();
};

module.exports = authMiddleware;
